India’s Computer Emergency Response Team (CERT-In) has issued a high-severity security advisory for Apple operating systems, warning that a vulnerability could allow attackers to execute arbitrary code on affected devices.
The vulnerability is tracked as CVE-2026-86950 and affects certain versions of iOS, iPadOS, macOS Sequoia and macOS Tahoe. CERT-In says the vulnerability is being actively exploited in an extremely sophisticated attack against specific targeted individuals.
Apple has already released security updates addressing the issue. Users running affected versions should update their devices as soon as possible.
What Is the Apple Vulnerability?
The vulnerability, identified as CVE-2026-86950, is an out-of-bounds write vulnerability in Apple’s CoreGraphics component.
CoreGraphics is used by Apple operating systems to process and render graphical content. According to Apple, processing a maliciously crafted file could trigger the vulnerability and potentially allow arbitrary code execution.
In simple terms, an attacker could potentially create a specially crafted file and attempt to exploit the vulnerable component when that file is processed by an affected device.
CERT-In has classified the issue as high severity and warned about the possibility of remote code execution and sensitive information disclosure.
CVE-2026-86950: Key Details
| Detail | Information |
|---|---|
| CVE | CVE-2026-86950 |
| Severity | High |
| Vulnerability Type | Out-of-bounds write |
| Affected Component | CoreGraphics |
| Potential Impact | Arbitrary code execution |
| Exploitation Status | Actively exploited in targeted attacks |
| CERT-In Advisory | CIVN-2026-0485 |
| Primary Vendor | Apple |
CERT-In specifically notes that the vulnerability is being actively exploited against targeted individuals, making timely patching particularly important for users and organizations running affected versions.
Which Apple Devices and Versions Are Affected?
CERT-In lists the following affected software versions:
- iOS: Versions before 26.7.1
- iPadOS: Versions before 26.7.1
- macOS Sequoia: Versions before 15.8.1
- macOS Tahoe: Versions before 26.7.1
Apple’s security documentation says iOS 26.7.1 and iPadOS 26.7.1 address the CoreGraphics issue on supported iPhone and iPad models.
Apple released these security updates on September 28, 2026.
How Can the Vulnerability Be Exploited?
The vulnerability involves an out-of-bounds write.
A specially crafted file can potentially cause the affected CoreGraphics component to write data outside an intended memory boundary. Under successful exploitation, this could result in arbitrary code execution.
Apple says it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals using versions of iOS before iOS 27.
This does not mean every Apple user is currently under attack. However, the fact that exploitation has been reported makes installing the available security updates important.
What Should iPhone and iPad Users Do?
Users should first check the software version installed on their device.
Go to:
Settings → General → Software Update
If an available security update is shown, install the latest supported version.
Apple’s security guidance recommends keeping Apple software updated because security releases address known vulnerabilities and other security issues.
Users should also be careful with unexpected files or attachments, particularly those received from unknown or untrusted sources.
What Should Mac Users Do?
Mac users should check:
Apple Menu → System Settings → General → Software Update
Users running affected versions of macOS Sequoia or macOS Tahoe should install the applicable security update.
The fixes include macOS Sequoia 15.8.1 and macOS Tahoe 26.7.1.
Why This CERT-In Warning Matters
The advisory is significant because this is not only a theoretical vulnerability.
CERT-In states that CVE-2026-86950 is being actively exploited in a sophisticated targeted attack.
The combination of:
- High severity
- Potential arbitrary code execution
- Malicious-file exploitation
- Reported active exploitation
makes patch management particularly important for organizations that use Apple devices.
Security teams should also maintain an updated inventory of company-managed Apple devices and verify that vulnerable operating-system versions are not still deployed.
What Businesses Should Check
Organizations using iPhones, iPads and Macs should consider checking:
- Device inventory
- Operating-system versions
- Pending security updates
- Mobile-device management policies
- Endpoint security controls
- Access logs for unusual activity
- Email and file-sharing controls
- Incident-response procedures
Organizations should pay particular attention to devices used for sensitive business operations, administrative access, financial systems and privileged accounts.
CVE-2026-86950 and Business Cybersecurity
A vulnerability affecting an employee device can become more important when that device has access to corporate systems.
For example, a compromised endpoint may have access to:
- Business email
- Cloud applications
- Internal dashboards
- Corporate documents
- Authentication systems
- Administrative services
This is why vulnerability management should not stop at identifying a CVE. Organizations should also understand which assets are exposed, whether vulnerable software exists in their environment and what additional security controls are available.
How to Reduce the Risk
Businesses and users can follow basic security practices:
1. Keep software updated
Install security updates promptly instead of postponing them indefinitely.
2. Avoid suspicious files
Do not open unexpected files or attachments from unknown sources.
3. Use strong account security
Enable multi-factor authentication where available.
4. Maintain device visibility
Organizations should maintain an accurate inventory of company-managed endpoints.
5. Monitor suspicious activity
Security teams should investigate unusual authentication, endpoint or network activity.
6. Regularly assess security
Organizations should periodically perform vulnerability assessments and security testing to identify weaknesses across applications, infrastructure and exposed systems.
What Is the Recommended Fix?
The primary remediation is to install the applicable Apple security update.
For affected versions, the relevant fixes include:
- iOS 26.7.1
- iPadOS 26.7.1
- macOS Sequoia 15.8.1
- macOS Tahoe 26.7.1
Users should refer to Apple’s official security documentation for device-specific availability.
Frequently Asked Questions
What is CVE-2026-86950?
CVE-2026-86950 is an out-of-bounds write vulnerability in Apple’s CoreGraphics component that could potentially allow arbitrary code execution when a maliciously crafted file is processed.
Which Apple devices are affected?
The affected software includes iOS and iPadOS versions before 26.7.1, macOS Sequoia versions before 15.8.1, and macOS Tahoe versions before 26.7.1.
Is CVE-2026-86950 being actively exploited?
Yes. CERT-In states that the vulnerability is being actively exploited in an extremely sophisticated attack against specific targeted individuals.
How can I protect my iPhone, iPad or Mac?
Install the latest applicable Apple security update and avoid opening suspicious or unexpected files. Apple recommends keeping its software up to date.
Is security testing useful for businesses using Apple devices?
Yes. Regular vulnerability assessment and security testing can help organizations identify outdated software, exposed systems, configuration weaknesses and other security risks. It should complement—not replace—prompt vendor patching.
Regular security testing and VAPT can help organizations identify vulnerabilities, exposed assets and security weaknesses before they become larger risks.
CyberNexora provides VAPT and cybersecurity assessment services to help businesses strengthen their security posture.
